Live data from Hacker News

Signal on Android: Images sent to wrong contacts

github.com

381–390 of 403 posts

Re: Signal on Android: Images sent to wrong contacts

#381
post #16

Earlier quoted context omitted.

Matrix is a solid replacement. Element isn't as easy to use but it's coming along. Quality-of-life features normal users expect like stickers, gifs, etc. are woefully lacking, but the important stuff (y'know, actual messaging) is solid. The most important thing to me is if Element screws up like Signal and starts pushing a shitcoin, I can swap clients without affecting my network.

Matrix is anything but a Signal replacement. It’s so convoluted and really questionable UX for personal communication. I think Signal (in its current form and direction) is a gone case but so is Matrix. Matrix is anyway chasing Slack not WhatsApp. I think that’s a smart move.

Matrix is a protocol, Element is a Slack-like app on Matrix.

It sounds like you have issues with Element as a replacement for Signal, which I totally get, but I think it's worth distinguishing Element from Matrix.

Element being the only full-featured Matrix app hopefully won't always be the case and it's Matrix's express goal to change that. Element is a single reference implementation -- if it's successful it could spawn many others supporting different UIs and use-cases, which we're already seeing with Fluffychat sporting a Signal-like chat interface.

I'm pushing my family and friends to use Matrix because that's the direction I want the world to go (open protocol with many different clients and servers communicating), not because we're already there today.

Re: Signal on Android: Images sent to wrong contacts

#382

Earlier quoted context omitted.

> I don't understand this attitude. Where did we go wrong as a discipline where making products that actually work is such an outlandish proposition? No other consumer product industry would talk like this. Part of it is cost/benefit ratio for the extra effort, part of it is market demands , part of it is lack of technology, part of it is unavoidable stuff like the halting problem. It's also worth remembering that Si…

This is a messaging app we're talking about here. There's nothing outrageously difficult or complex that hasn't already been done 25 years ago. If 36 people and $100 million in funding is not enough to make a messaging app that doesn't suck, what _is_ required and why is it more than that?

> This is a messaging app we're talking about here. There's nothing outrageously difficult or complex that hasn't already been done 25 years ago.

If you think it's so easy, be your own change and do it, and then we can judge the results.

> If 36 people and $100 million in funding is not enough to make a messaging app that doesn't suck, what _is_ required and why is it more than that?

You're assuming there's a solution of a certain form to get you what you want, but maybe it's your assumption that's wrong.

I mean, there are formally verified systems that might be like what you're asking, but they're both 1) very expensive, 2) extremely feature poor.

Re: Signal on Android: Images sent to wrong contacts

#383

Earlier quoted context omitted.

Signal typically delay releasing the server source code, so the latest version of the server is not open source. In one case it took them almost a year (no public commits between 20 April 2020 and 6 April 2021). https://github.com/signalapp/Signal-Android/issues/11101#iss... Among the official reasons given was staying ahead of spammers. In this instance it was also speculated that the payment function which they wer…

One of the biggest problems with open source software is enormously entitled users; who don't pay for it, don't work on it, yet feel remarkably offended when some whim of theirs is not catered to. Just saying.

Are you trying to subtly accuse chithanh of something? If so I would request that you do it explicitly instead of in a passive-agressive way.

Regardless, their post contained only factual statements relevant to the discussion. I noticed no entitlement.

Re: Signal on Android: Images sent to wrong contacts

#384

Earlier quoted context omitted.

It comes from the halting problem. People can be more careful writing code, but it is impossible to be certain about all the things code will or won't do. Even very simple programs can have flaws that get found and fixed years later. It happens all the time. We need to be open and honest about the possibility that our code may act in ways we don't foresee.

If this was actually true, we wouldn't have safety critical software systems that have been running for decades without fatal bugs.

> If this was actually true, we wouldn't have safety critical software systems that have been running for decades without fatal bugs.

Not hitting a bug is not the same as not having a bug. I'd bet money that whatever system you're talking about has bugs. Plus, the system may be far simpler than you assume.

Re: Signal on Android: Images sent to wrong contacts

#385

Earlier quoted context omitted.

I don't think Signal has many devs[0] and if you look at the contributors[1] you can see that Grayson is pretty much the only dev for the Android app. So seeing a second dev get involved is probably them freaking out. [0] Personally I believe this is a big bump in the road for Signal and is why a lot of people are frustrated. About promises about things like usernames (it is no longer early 2021), channels, and every…

No, Signal does not get to play the limited resources card when they so firmly discourage 3rd parties from working on their project.

Not true

Re: Signal on Android: Images sent to wrong contacts

#386

Earlier quoted context omitted.

If this is the case, then we should just say: Signal is not secure because they have limited resource and cannot invest in an area with Security adequately.

Or perhaps we drop the pretence of anything being absolute ('secure' vs 'not secure') and have a more honest discussion about the different threats and where different products do better or worse? I'm sure Whatsapp is much better in being able to resource their security measures, yet being owned by Facebook, and being closed-source diminishes their security in other ways.

I personally trust whatsapp, great product

Re: Signal on Android: Images sent to wrong contacts

#387

Earlier quoted context omitted.

Matrix is anything but a Signal replacement. It’s so convoluted and really questionable UX for personal communication. I think Signal (in its current form and direction) is a gone case but so is Matrix. Matrix is anyway chasing Slack not WhatsApp. I think that’s a smart move.

Matrix is a protocol, Element is a Slack-like app on Matrix. It sounds like you have issues with Element as a replacement for Signal, which I totally get, but I think it's worth distinguishing Element from Matrix. Element being the only full-featured Matrix app hopefully won't always be the case and it's Matrix's express goal to change that. Element is a single reference implementation -- if it's successful it could…

I should have been clear about that. Yes, I am aware that Matrix and Vector>Riot>Element are different.

In fact Matrix as a protocol even less of a Signal replacement. People get perturbed by tiny amount of sign up friction and imagine self hosting. But then if you assume, and that's what I did assume, that for the sake of considering Matrix/Element as a replacement of Signal we stick to matrix.org server. That essentially makes Matrix as Signal replacement.

Also, when people usually talk about Matrix being adopted by masses they are talking about Matrix on matrix.org (or that's my understanding which may be incorrect as well).

Re: Signal on Android: Images sent to wrong contacts

#388

Earlier quoted context omitted.

Matrix is a protocol, Element is a Slack-like app on Matrix. It sounds like you have issues with Element as a replacement for Signal, which I totally get, but I think it's worth distinguishing Element from Matrix. Element being the only full-featured Matrix app hopefully won't always be the case and it's Matrix's express goal to change that. Element is a single reference implementation -- if it's successful it could…

I should have been clear about that. Yes, I am aware that Matrix and Vector>Riot>Element are different. In fact Matrix as a protocol even less of a Signal replacement. People get perturbed by tiny amount of sign up friction and imagine self hosting. But then if you assume, and that's what I did assume, that for the sake of considering Matrix/Element as a replacement of Signal we stick to matrix.org server. That essen…

> Also, when people usually talk about Matrix being adopted by masses they are talking about Matrix on matrix.org (or that's my understanding which may be incorrect as well).

No idea how you got that understanding. With respect to adoption the server does not matter at all (though many consider it advantageous if it is not matrix.org)

Re: Signal on Android: Images sent to wrong contacts

#389
post #343

Earlier quoted context omitted.

By not allowing 3rd parties apps to coexist with official signal app. (Using same servers)

Signal placing restrictions on who can use their service has nothing to do with whether or not people can contribute to the codebase.

It does. There is less incentive to work on a Signal client fork if it can't be used to interoperate with the Signal service.

Re: Signal on Android: Images sent to wrong contacts

#390
post #269

Earlier quoted context omitted.

But Signal isn't just a chat app, it's an app with a very strong focus on security, and you can't have backward compatibility with security. Otherwise you end up with some servers still implementing SSLv3 years after its due date, or GPG with settings that make it insecure by default. You must force everyone in the ecosystem to use the latest version of the API, but even that is not enough: if there's an issue with t…

> You must force everyone in the ecosystem to use the latest version of the API Couldn't Signal just announce a "flag day"[0] in advance and say that their servers would block connections from clients that don't support a specific version of the API by that date? For non-essential upgrades, the API change should be announced well in advance, but client developers might be given just a few days notice before security…

They could, but again it's not just about the API, the client itself must also be secue enough. That means enforcing security in some way to third parties, or just blocking them until they've solved all issues. And in practice if you let people migrate at their own pace they just won't migrate until clients complain.
Post reply on HN